Secret communication system and method for operation and maintenance service management based on block chain technology
By using a three-layer data framework and blockchain technology, the security and traceability issues of data communication systems in operation and maintenance service management are solved, achieving efficient data transmission and risk response, and improving the system's security protection and data recovery capabilities.
Patent Information
- Application Number
- CN202511165062.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-20
- Publication Date
- 2025-12-12
AI Technical Summary
Existing data communication systems in operation and maintenance service management suffer from insufficient security, integrity, and traceability during data transmission and storage, making it difficult to prevent data leakage and unauthorized access. Furthermore, the lack of effective identity binding, flow control, and protocol compatibility mechanisms leads to low data transmission efficiency and delayed risk response.
A three-layer data framework is adopted, including an operations and maintenance layer, a data center layer, and a blockchain layer. Through full data sharding encryption, independent data interfaces, and a blockchain encryption recording module, the encryption, recording, and monitoring of cross-layer data interaction are realized. Combined with dynamic encryption strategies and smart contract verification, a cross-layer transmission control module is constructed to improve system security and responsiveness.
It improves the confidentiality and security of data transmission, enhances data recovery efficiency, optimizes data transmission efficiency, reduces network bandwidth consumption, and realizes collaborative verification and dynamic risk response of multi-layer data framework, thereby improving the system's anti-attack capability and data recovery capability.
Smart Images

Figure CN121125179A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of secure communication technology for operation and maintenance, and specifically relates to a secure communication system and method for operation and maintenance service management based on blockchain technology. Background Technology
[0002] With the rapid development of information technology and the deepening of digital transformation, enterprise operation and maintenance service management is facing increasingly severe data security challenges. Traditional operation and maintenance communication systems are highly susceptible to data leakage, unauthorized access, and malicious attacks during data transmission and storage due to the lack of effective security mechanisms and traceability. This seriously threatens the core data assets and business continuity of enterprises. Especially in complex operation and maintenance environments involving multiple parties and cross-departmental collaboration, how to ensure the confidentiality, integrity, and trustworthiness of data circulation has become a key issue that urgently needs to be addressed in the current operation and maintenance field. Blockchain technology, with its decentralized, tamper-proof, and traceable characteristics, provides a new technical path and solution for building a highly secure confidential communication system. It is expected to improve the data security protection capabilities of operation and maintenance service management and achieve end-to-end data trust and collaboration.
[0003] Problems with existing technology: Existing data communication systems in operations and maintenance service management typically employ a centralized architecture. Data transmission and storage rely on specific servers or data centers. During data transmission, encryption protocols such as VPN and SSL / TLS are generally used to encrypt the channel to ensure the confidentiality of data transmission. Data access permissions are usually managed by identity authentication and access control lists (ACLs). In terms of logging, the system records operation logs and transmission logs for post-event auditing. However, this centralized architecture has limitations in terms of security, data integrity, and traceability when facing internal attacks, single points of failure, or advanced persistent threats. For example, data centers may become targets of attacks, and once compromised, stored data and logs may be tampered with or stolen, making it difficult to achieve end-to-end trust verification. In addition, the complexity of cross-layer data interaction also increases the difficulty of security management, making it difficult to achieve efficient detection and response to abnormal behavior. Existing data communication systems in operations and maintenance service management suffer from issues such as low confidentiality and security. Under traditional centralized architectures, data is vulnerable to man-in-the-middle attacks, data tampering, or unauthorized access during transmission and storage, making it difficult to effectively prevent data leaks. Furthermore, data integrity and traceability are insufficient. In complex cross-layer data transmission processes, existing technologies struggle to ensure the original integrity of data and lack effective end-to-end traceability mechanisms, making it difficult to detect and accurately locate abnormal behavior in a timely manner. Traditional data interfaces also lack effective identity binding, flow control, and protocol compatibility mechanisms, making them susceptible to unauthorized requests, DDoS attacks, or other unforeseen circumstances. Protocol incompatibility leads to low data transmission efficiency, risks of data leakage, and a lack of multi-layered data framework collaborative verification mechanisms. In particular, when multi-layered data frameworks operate collaboratively, the lack of unified and efficient verification and collaborative blocking mechanisms results in insufficient consistency verification and abnormal data processing capabilities at each layer, making it difficult to cope with complex data anomalies. Furthermore, the response to risk management and dynamic response is slow, and when facing potential security risks, there is a lack of ability to dynamically adjust encryption strategies and transmission behaviors according to risk levels. In addition, the real-time monitoring and automatic alarm mechanisms of the audit chain are imperfect, resulting in delayed risk response and difficulty in effectively avoiding high-risk transmission scenarios. Summary of the Invention
[0004] The purpose of this invention is to provide a secure communication system and method for operation and maintenance service management based on blockchain technology, which can improve the confidentiality and security of data communication in operation and maintenance service management, effectively prevent data leakage and unauthorized access, respond to data anomalies, enhance system security protection capabilities, and avoid potential risks.
[0005] The specific technical solution adopted by this invention is as follows: A secure communication system for operation and maintenance service management based on blockchain technology, comprising: A three-tier data framework, comprising: The operation and maintenance layer is deployed on the intranet. The operation and maintenance layer is used to store operation and maintenance service data, run operation and maintenance systems and communication systems, and output full data fragments and encrypted storage to the operation and maintenance layer. The data center layer is used to store real-time updated secure communication protocols, defense system patches, and encryption policy libraries. It interacts with the operation and maintenance layer and the blockchain layer through an independent data interface, and only allows authorized cross-layer data requests. The blockchain layer is used to record all data interaction behaviors between the three-layer data framework, verify the legality of cross-layer transmission requests through smart contracts, and generate encrypted transmission channels. as well as A cross-layer transmission control module is used to implement data transmission, data encryption, and data transmission monitoring in a three-layer data framework. A blockchain encryption recording module is used to realize cross-layer data interaction encryption, recording, and monitoring within a three-layer data framework.
[0006] As an optional embodiment, the cross-layer transmission control module includes: Dynamic encryption strategy engine: Matches encryption algorithms based on data sensitivity levels; Transmission direction control unit: Based on a blockchain-stored trusted communication whitelist, it restricts the transmission of data from the data center layer to the operation and maintenance layer, including the authorized data size, data type, data source and communication protocol; Hierarchical permission response mechanism: When the operations and maintenance layer requests data, it must submit identity credentials and verify them through zero-knowledge proof. Permission changes are synchronized on the blockchain in real time.
[0007] As an optional embodiment, the blockchain encryption recording module generates a unique hash value for all cross-layer data interactions and writes it into the blockchain layer, and records it in the log of the blockchain layer to realize full-link traceability of cross-layer data interactions, as well as triggering smart contract alarms and freezing the corresponding interfaces for abnormal transmission behavior.
[0008] As an optional embodiment, the independent data interface includes: Interface identity binding unit: Each interface is uniquely associated with a blockchain layer address to prevent illegal interface requests; Traffic rate limiting controller: Limits the rate of cross-layer data transmission to prevent data leakage or DDoS attacks; Protocol Adaptive Converter: Automatically adapts to the communication protocols between the three-layer data framework, achieving compatibility for cross-layer data interaction.
[0009] As an optional embodiment, the blockchain layer includes three-dimensional links, which are independently configured and interact with each other through a configured cross-chain protocol; The three-dimensional link includes an operation and maintenance chain, a data chain, and an audit chain. The operation and maintenance chain is used to record the operation logs and permission changes of the operation and maintenance layer. The data chain is used to store the update records and encryption policies of the central layer. The audit chain is used to record the full behavior of cross-layer transmission.
[0010] A secure communication method for operation and maintenance service management based on blockchain technology includes the following steps: In a three-tier data framework, cross-tier data transmission requests are received through independent data interfaces; The blockchain layer verifies the validity of the requester's identity signature, while the operation and maintenance chain verifies the matching of the permission level, and the data chain verifies whether the target address is in the trusted communication whitelist stored in the blockchain. After verification, the blockchain layer dynamically matches encryption algorithm combinations based on the data sensitivity level information stored in the operation and maintenance chain, performs fragmented encryption processing on the transmitted data, and generates encrypted transmission channel parameters in the data chain; The encrypted data fragments are transmitted to the target data layer through independent data interfaces. The operation and maintenance layer collects at least k key fragments to reassemble the data, and the data center layer only provides the amount of data authorized by the audit chain. The three-layer data framework collaboratively records the complete cross-layer transmission behavior, the operation and maintenance chain records operation logs, the data chain stores encrypted parameters, and the audit chain stores the full-link transmission information, realizing data consistency verification through the three-dimensional link.
[0011] As an optional implementation, the three-tier data framework collaboration method includes the following steps: The operations and maintenance layer is deployed on the intranet and interacts with the blockchain layer only through an independent data interface. The stored operations and maintenance data is saved in a full-scale sharded and encrypted manner. When data needs to be updated, an update request is sent to the blockchain layer through the independent data interface. After receiving an update request from the operations and maintenance layer, the blockchain layer verifies the requester's permissions through the operations and maintenance chain and queries the trusted communication whitelist through the data chain to confirm the data center layer's push permissions. The permission verification result is recorded to the audit chain in real time. Based on the permission verification results of the blockchain layer, the data center layer pushes updated data to the operations and maintenance layer through an independent data interface. The push process is monitored by the blockchain layer, and the amount of data transmitted by the operations and maintenance layer is limited by the authorization of the audit chain. During data transmission, the three-dimensional link forms a collaborative verification mechanism through cross-hash binding. The operation and maintenance chain block header contains the latest block hash value of the data chain, and the data chain block header contains the latest block height of the audit chain. Any abnormal data in any link of the three-dimensional link will trigger the three-dimensional link collaborative blocking mechanism.
[0012] As an optional embodiment, the dynamic encryption and risk management method of the three-layer data framework includes the following steps: When the blockchain layer detects that the risk score of cross-layer transmission exceeds the threshold, it notifies the operation and maintenance layer through the operation and maintenance chain to reduce the amount of data transmission or stop data transmission. At the same time, it instructs the data center layer to switch to a quantum-resistant encryption algorithm through the data chain. The operations and maintenance layer adjusts its data receiving strategy according to the instructions of the operations and maintenance chain, only receiving key data authorized by the audit chain, and at the same time feeding back the system status to the blockchain layer; The data center layer dynamically adjusts the push strategy according to the instructions of the data chain, and adopts fragmented encrypted transmission for high-risk transmissions, with each fragment of data processed using a different encryption algorithm; The audit chain monitors the three-dimensional link collaboration status in real time. When an anomaly in data consistency is detected, it automatically generates a full-link traceability report and triggers a smart contract to freeze the relevant data interfaces.
[0013] According to another aspect of the present invention, a computer-readable storage medium is also provided, the storage medium storing a computer program that, when executed by a processor, implements the method described in any one of the preceding embodiments.
[0014] According to another aspect of the present invention, a computer program product is also provided, including a computer program that, when executed by a processor, implements the method described in any one of the preceding embodiments.
[0015] The technical effects achieved by this invention are as follows: This invention, through the deployment of a three-layer data framework, combines full data sharding encryption with blockchain records, which not only provides data confidentiality protection but also improves data recovery efficiency. When a shard is damaged, the system only needs to restore k shards to reconstruct the data, instead of fully restoring all n shards.
[0016] This invention enables the data chain and audit chain to automatically provide necessary verification information when an anomaly occurs in a certain chain (such as the operation and maintenance chain), helping the abnormal chain to recover quickly and forming a system self-healing capability.
[0017] This invention, an independent data interface protocol adaptive converter, not only solves the protocol compatibility problem but also optimizes data transmission efficiency. By intelligently selecting the optimal transmission protocol, data transmission speed is improved, redundant transmission of interfering data is reduced, and network bandwidth consumption is lowered.
[0018] This invention not only strengthens encryption when the system detects a potential threat, but also automatically adjusts the data sharding strategy (such as increasing the number of shards n), forming dual protection and making it exponentially more difficult for attackers to crack.
[0019] This invention implements detailed functional partitioning of the blockchain layer through a three-dimensional link framework, forming a chain-like framework. This addresses the issues of poor collaborative verification mechanisms and dynamic response capabilities in risk management within multi-layered data frameworks. By constructing a three-dimensional link framework, complex blockchain functions are broken down into three chains according to business logic. Each chain focuses on data recording and verification in a specific domain, avoiding performance limitations and security vulnerabilities caused by the overload of a single chain. A cross-verification mechanism is established between the three-dimensional chains, requiring collaborative verification from other chains for any operation, thus forming a closed-loop verification security model and improving the system's resistance to attacks.
[0020] In this invention, key data from each chain has a copy stored in other chains, creating data redundancy and mutual verification. This ensures that even if one chain is attacked, the system can still restore data integrity through other chains, thereby achieving functional coupling and verification mechanisms between the three-dimensional links to further enhance data recovery capabilities. Attached Figure Description
[0021] Figure 1 This is a schematic diagram of the secure communication system structure for operation and maintenance service management of this invention; Figure 2 This is a schematic diagram of the cross-layer transmission control module in this invention; Figure 3 This is a schematic diagram of the structure of the independent data interface in this invention; Figure 4 This is a schematic diagram of the blockchain layer structure in this invention; Figure 5 This is a flowchart of the secure communication method for operation and maintenance service management in this invention; Figure 6 This is a flowchart of the data consistency verification method in this invention; Figure 7 This is a flowchart of the three-layer data framework collaboration method in this invention; Figure 8 This is a flowchart of the dynamic encryption and risk management method of the three-layer data framework in this invention. Detailed Implementation
[0022] To make the objectives and advantages of this invention clearer, the invention will be specifically described below with reference to embodiments. It should be understood that the following text is merely used to describe one or more specific embodiments of the invention and does not strictly limit the scope of protection specifically claimed by the invention.
[0023] It should be noted that the terms "first," "second," etc., used in this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0024] According to an embodiment of the present invention, a method embodiment for a secure communication method for operation and maintenance service management based on blockchain technology is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0025] like Figure 1As shown, a secure communication system for operation and maintenance service management based on blockchain technology includes: Three-tier data framework, and The cross-layer transmission control module is used to implement data transmission, data encryption, and data transmission monitoring in a three-layer data framework. The blockchain encrypted record module is used to implement cross-layer data interaction encryption, recording, and monitoring within a three-layer data framework.
[0026] The three-tier data framework includes: The operations and maintenance layer is deployed on the intranet. It is used to store operations and maintenance service data, run operations and maintenance systems and communication systems, and output all data in fragmented and encrypted form to the operations and maintenance layer. The data center layer stores real-time updated secure communication protocols, defense system patches, and encryption policy libraries. It interacts with the operations and maintenance layer and the blockchain layer through an independent data interface, allowing only authorized cross-layer data requests. The blockchain layer records all data interactions between the three-layer data framework, verifies the legitimacy of cross-layer transmission requests through smart contracts, and generates encrypted transmission channels.
[0027] Based on the above, a three-layer data framework is constructed, and blockchain technology is used to achieve secure control over cross-layer data interaction.
[0028] The operations and maintenance (O&M) layer is the core layer, deployed within the intranet and physically isolated from the external network, providing a high level of security protection to ensure that external attackers cannot directly or indirectly access the O&M layer. The O&M layer is used to store O&M service data, run O&M systems and communication systems, such as the daily O&M tasks of running a highway network toll collection system, including but not limited to core functions such as equipment monitoring, fault diagnosis, configuration management, and security auditing, or running an enterprise's internal O&M system.
[0029] Furthermore, the output full data is stored in the operations and maintenance layer using a sharded encrypted storage method. All stored operations and maintenance service data is split into n data shards, each of which is encrypted using an independent encryption key and then stored separately.
[0030] Furthermore, the independent encryption key is dynamically changed in real time among n data shards. The changing methods include cyclic change, random change, cross change, etc. Multiple groups of dynamic verification codes are generated according to the dynamic change rules, and the corresponding verification codes are stored in a physical external storage manner. For example, financial data, warehousing data, and file data are stored in shards. The financial data includes one or more dynamic verification codes. When the financial data changes, a new encryption key and dynamic verification codes are generated. A corresponding decoding verification code is generated through the dynamic verification codes. The generation of this decoding verification code unlocks and verifies the verification codes stored in the external storage. Only after unlocking or verification can the data be read, modified, etc. The warehousing data and file data are treated in the same way.
[0031] The dynamic verification codes generated for financial data, warehousing data, and file data are alternately changed over time, or the dynamic verification codes are generated in a non - regular manner through system settings. Each data shard is encrypted using a different encryption algorithm or key. For example, the first shard uses the SM4 algorithm, the second shard uses the AES - 256 algorithm, and the third shard uses the national cipher SM9 algorithm. Each independent encryption key is unique.
[0032] As an optional embodiment, the number of data shards n is dynamically adjusted according to the data sensitivity level. Usually, n≥3. For highly sensitive data, n≥5 can be set. Each n also includes at least one corresponding dynamic verification code.
[0033] As an optional embodiment, the storage locations of data shards are decentralized. Different shards are stored in different physical or logical storage areas at the operation and maintenance layer. For example, it is set that all or part of the financial data is stored in the first shard, or all or part of the financial data and warehousing data are stored in the first shard, etc. The corresponding unique dynamic verification codes are generated according to the above - mentioned storage method.
[0034] Furthermore, when data is recombined, a sufficient number of shards (at least k, 1 < k≤n) need to be collected and decrypted and recombined through the threshold signature technology. Here, k is an integer greater than 1 and less than or equal to the total number of key shards. In high - risk scenarios, k = n.
[0035] According to the above, through the full - volume data sharding encryption technology, the risk of all data loss caused by data loss can be prevented. Especially, even if an attacker obtains some data shards, due to the lack of sufficient shard quantity and corresponding keys, the original data cannot be restored, which greatly improves data security. Moreover, it is more difficult to obtain the full - volume data. In addition, through the method of dynamic verification codes, the risk of internal personnel stealing data can also be avoided. Combining with the data log at the blockchain layer, the corresponding operators when the data changes can be identified, realizing the traceability of data.
[0036] In addition, the data center layer serves as the system's data update and policy management center, primarily used for the maintenance of the operation and maintenance system and real-time updates of operation and maintenance data.
[0037] Furthermore, the data center layer is used to store real-time updated secure communication protocols, defense system patches, and encryption policy libraries, and provides a unique interaction channel between the data center layer, the operations and maintenance layer, and the blockchain layer through an independent data interface.
[0038] Furthermore, by binding the identity of independent data interfaces, each independent data interface is uniquely associated with a blockchain address, ensuring the traceability and authenticity of interface calls. When transmitting content, only authorized cross-layer data requests are allowed to pass, and unauthorized data requests will be automatically blocked. During data transmission, by supporting and recording multiple communication protocols and realizing the conversion of multiple communication protocols during transmission, smooth communication between different layers is ensured.
[0039] As an optional implementation, the data center layer adopts an incremental update strategy, pushing only the necessary update content to reduce data transmission volume, reduce security risks, and the update content is screened through signature verification to ensure the reliability of data sources and the integrity of content.
[0040] As an optional implementation, the data center layer can be deployed via a network, such as on a cloud server, central control server, or secondary central server. It can also be deployed in an intranet, enabling independent updates, optimizations, and data updates for the operation and maintenance layer system. For example, an enterprise can deploy the data center layer in its intranet to achieve independent updates and maintenance of the entire system and data.
[0041] The block layer provides an immutable recording and verification mechanism for the secure communication system of the entire operation and maintenance service management. The blockchain layer is specifically used to record all data interaction behaviors between the three-layer data framework, forming a complete operation audit log, which includes: Interactive timestamps; Data source and destination address; The hash value of the transmitted data; Encryption algorithm and key identifier; Operator's identity information (privacy protection measures are taken; viewing permissions can be selectively granted after authorization is obtained); Interaction result (success / failure); Interactive behavior (operational behavior, including non-compliant operations such as violations); Furthermore, smart contracts are used to verify the legitimacy of cross-layer transmission requests. When a cross-layer transmission request is received, the blockchain layer automatically triggers the corresponding smart contract to execute the following verification steps: a. Identity verification: Verify the validity of the requester's digital signature to ensure the authenticity of the request source; b. Permission verification: Check whether the requester has the right to perform the operation to prevent unauthorized access; c. Data integrity verification: Ensure that the transmitted data has not been tampered with through hash comparison; d. Whitelist verification: Confirm whether the target address is in the trusted communication whitelist.
[0042] After the above steps are verified, the blockchain layer generates a secure encrypted transmission channel. The channel key is dynamically generated, and a different key is used for each transmission. Multiple encryption algorithms are combined to enhance confidentiality. The channel is time-sensitive; it will be closed after a period of time to prevent key rule leakage caused by prolonged access.
[0043] Based on the above, the blockchain layer can ensure that data is not easily tampered with, logs are secure and stable, and data between the operation and maintenance layer and the data center layer is tamper-proof.
[0044] The cross-layer transmission control module is the system control unit, responsible for realizing data transmission between the three-layer data framework, monitoring and managing whether the data transmission between the three-layer data framework complies with the security policy, automatically matching encryption algorithms and encryption strength according to the data sensitivity level, monitoring the transmission status in real time, recording transmission logs and detecting abnormal behavior, and achieving confidentiality and data integrity of data during cross-layer transmission through the set access control and encryption policies.
[0045] The blockchain confidential recording module provides security for the three-layer data framework, and is responsible for encrypting, recording and monitoring cross-layer data interactions. The blockchain confidential recording module performs end-to-end encryption on all cross-layer data to ensure the confidentiality of data during transmission. It writes the encrypted data hash value into the blockchain (layer) to generate an immutable record, monitors data interaction behavior in real time, detects abnormal patterns and triggers alarms, and achieves collaborative monitoring and protection with the blockchain layer.
[0046] The principle of the above embodiment is as follows: layered protection is achieved based on a three-layer data framework. By dividing the system into three logical layers—the operation and maintenance layer, the data center layer, and the blockchain layer—each layer undertakes different security responsibilities, forming a defense-in-depth system. Even if one layer is breached, the other layers can still provide effective protection and data integrity.
[0047] Furthermore, by employing techniques such as secret sharing in threshold cryptography, the data is split into multiple fragments, each of which is independently encrypted and stored. Only by collecting a sufficient number of fragments (k) can the original data be recovered, which greatly improves data security. The mathematical principle is based on the Shamir secret sharing scheme, and its security depends on the polynomial interpolation problem over a finite field.
[0048] Furthermore, through the distributed ledger technology of blockchain, key information of all cross-layer data interactions is recorded in immutable blocks, and the authenticity and consistency of the records are ensured through a consensus mechanism, providing accurate and reliable data records for subsequent audits.
[0049] Furthermore, by encoding security policies into smart contract code and automatically executing verification logic, the operational threshold for operators is lowered. Through a responsible three-layer logic layer, the difficulty of stealing confidential data is increased. As a decentralized trust intermediary, smart contracts ensure that all operations are verified, preventing human negligence or malicious operations.
[0050] Furthermore, by deploying a three-layer data framework, the combination of full data shard encryption and blockchain records not only provides data confidentiality protection but also improves data recovery efficiency. When a shard is damaged, the system only needs to restore k shards to rebuild the data, instead of fully restoring all n shards.
[0051] Furthermore, when an anomaly occurs in a certain chain (such as the operation and maintenance chain), the data chain and audit chain can automatically provide the necessary verification information to help the abnormal chain recover quickly, forming the system's self-healing capability.
[0052] Furthermore, the independent data interface protocol adaptive converter not only solves the protocol compatibility problem, but also optimizes data transmission efficiency. By intelligently selecting the optimal transmission protocol, the data transmission speed is improved, redundant transmission of interfering data is reduced, and network bandwidth consumption is lowered.
[0053] Furthermore, when the system detects a potential threat, it will not only strengthen the encryption but also automatically adjust the data sharding strategy (such as increasing the number of shards n), forming a double protection that makes it exponentially more difficult for attackers to crack.
[0054] As an optional embodiment, refer to the appendix Figure 2 The cross-layer transmission control module includes: Dynamic encryption strategy engine: Matches encryption algorithms based on data sensitivity levels; Transmission direction control unit: Based on a blockchain-stored trusted communication whitelist, it restricts the transmission of data from the data center layer to the operation and maintenance layer, including the authorized data size, data type, data source and communication protocol; Hierarchical permission response mechanism: When the operations and maintenance layer requests data, it must submit identity credentials and verify them through zero-knowledge proof. Permission changes are synchronized on the blockchain in real time.
[0055] The dynamic encryption strategy engine divides data assessment into multiple assessment levels based on data sensitivity, such as L1 (public information), L2 (internal information), L3 (sensitive information), L4 (confidential information), and L5 (top secret information). The assessment criteria are data type (configuration data, log data, user data, etc.), data source (internal system, external interface, etc.), and data purpose (monitoring, analysis, decision-making, etc.).
[0056] Its evaluation algorithm uses: Sensitivity score = W1 × Type weight + W2 × Source weight + W3 × Purpose weight; W1, W2, and W3 are adjustable weighting coefficients.
[0057] The dynamic encryption strategy engine updates the encryption strategy regularly based on historical attack pattern data stored on the blockchain. Before each data transmission, it retrieves the latest encryption strategy from the blockchain and dynamically adjusts the sensitivity threshold based on recent security incidents to improve the defense capabilities against new viruses or intrusion methods.
[0058] Furthermore, the transmission direction control unit implements data transmission control based on a trusted communication whitelist stored on the blockchain. The whitelist is maintained by the operations and maintenance administrator through smart contracts, recording the allowed IP addresses, port ranges, and protocol types. When the data center layer transmits data to the operations and maintenance layer, it verifies whether the target address is on the whitelist and checks the size of the transmitted data (such as limiting the size of a single data packet), data type (only predefined formats are allowed, such as updating system data, updating data, etc.), and communication protocol (only HTTPS or MQTT-Secure). The transmission direction control unit collaborates with the audit chain of the blockchain layer, and any unauthorized attempts are recorded and trigger alarms.
[0059] Furthermore, the hierarchical access control mechanism uses zero-knowledge proof technology to verify identity. Operations personnel can prove their legitimacy without submitting their original password, thus improving response speed. The system divides users into four levels of access: system administrator, security administrator, operations operator, and auditor. Changes to each level of access are synchronized to the blockchain layer in real time. When the operations layer requests data, it must provide identity credentials. After verification by the blockchain layer through the zero-knowledge proof protocol, it only returns authorized data fragments.
[0060] Based on the above, through the collaborative mechanism within the cross-layer transmission control module, when the system detects an abnormal access pattern, the dynamic encryption strategy engine automatically increases the encryption strength, while the transmission direction control unit narrows the whitelist range, and the permission hierarchical response mechanism tightens access permissions. This constitutes a collaborative mechanism within the cross-layer transmission control module, making it exponentially more difficult for attackers to crack the code and improving the detection rate of persistent threats.
[0061] As an optional implementation, the blockchain encryption recording module generates a unique hash value for all cross-layer data interactions and writes it into the blockchain layer, and records it in the blockchain layer's log to achieve full-link traceability of cross-layer data interactions, as well as triggering smart contract alarms and freezing the corresponding interfaces for abnormal transmission behavior.
[0062] As described above, the blockchain encrypted record module is integrated with the three-layer data framework and the cross-layer transmission control module to generate a unique hash value for each cross-layer data interaction. This hash value contains key metadata such as data source, target, timestamp, data size, and encryption algorithm identifier. Unlike traditional log recording, the blockchain encrypted record module writes the hash value directly into the immutable block of the blockchain layer, rather than a regular database, to ensure the authenticity and reliability of the record.
[0063] The hash value of the current interaction contains the hash digest of the previous interaction, forming a continuous traceability chain. When it is necessary to trace a data transmission, the system can start from any node, trace back the complete transmission path through the hash chain, accurately record the operation, work in conjunction with the transmission direction control unit, clarify the transmission content and restore the decision basis for the transmission reason, so as to realize the full-link traceability function.
[0064] The detection of abnormal transmission behavior adopts a multi-dimensional analysis model to monitor indicators such as transmission frequency, sudden changes in data volume, and protocol anomalies. When suspicious behavior is detected, such as the operations and maintenance layer requesting a large amount of core data outside of working hours, the smart contract is immediately triggered to execute a three-level response: Level 1 alerts the administrator, Level 2 limits the transmission rate, and Level 3 freezes the relevant interfaces.
[0065] Furthermore, the blockchain encryption record module works in synergy with the dynamic encryption strategy engine. When an anomaly is detected, not only is the interface frozen, but a higher level of encryption strategy is also automatically triggered, making it impossible for attackers to decrypt even if they obtain some data, thus reducing the risk of data leakage. All operation records are synchronized to the three-dimensional link in real time to ensure the consistency of data in the audit chain, operation and maintenance chain, and data chain.
[0066] As an optional embodiment, refer to the appendix Figure 3 Independent data interfaces include: Interface identity binding unit: Each interface is uniquely associated with a blockchain layer address to prevent illegal interface requests; Traffic rate limiting controller: Limits the rate of cross-layer data transmission to prevent data leakage or DDoS attacks; Protocol Adaptive Converter: Automatically adapts to the communication protocols between the three-layer data framework, achieving compatibility for cross-layer data interaction.
[0067] As described above, the independent data interface serves as the sole interaction channel within the three-layer data framework. The interface identity binding unit assigns a unique blockchain address to each physical interface and generates an interface identity certificate using ECC asymmetric encryption. This certificate is synchronized in real-time with the operation and maintenance chain of the blockchain layer. When an interface is called, the system verifies whether the certificate signature matches the blockchain record. Any forged interface requests will be rejected. The independent data interface is linked to the cross-layer transmission control module's permission-based response mechanism to ensure that only authorized interfaces can trigger specific permission operations.
[0068] Furthermore, the traffic rate limiting controller employs algorithms such as the token bucket to dynamically adjust the transmission rate based on the data sensitivity level. Core data transmission is limited to 10Mbps, sensitive data to 50Mbps, and general data to 200Mbps, etc. When a short-term traffic surge is detected (such as exceeding the threshold by 300% within 1 second), tiered rate limiting is immediately initiated: for example, the transmission rate is first reduced to 50%, and if the abnormality continues, it is reduced to 10%, ultimately triggering the smart contract to freeze the interface, which can effectively defend against simulated DDoS attacks.
[0069] Furthermore, the protocol adaptive converter incorporates multiple commonly used protocol parsers, automatically identifying and converting protocol formats such as HTTP and MQTT. When the data center layer uses the MQTT protocol to push updates, while the operations and maintenance layer only supports HTTPS, the converter completes the protocol conversion in real time, ensuring data adaptation for transmission. Working in conjunction with the dynamic encryption strategy engine, it maintains data encryption during the conversion process, avoiding decryption risks caused by protocol conversion.
[0070] Furthermore, if an attacker attempts to launch a DDoS attack by forging an interface, the identity binding unit will identify the illegal request, the traffic rate limiter will automatically reduce the speed, and the protocol converter will detect abnormal protocol characteristics. Through collaborative protection, an alarm mechanism will be triggered, which can improve the response speed.
[0071] As an optional embodiment, refer to the appendix Figure 4 The blockchain layer includes three-dimensional links, which are set up independently and interact with each other through a cross-chain protocol. The three-dimensional link includes the operation and maintenance chain, the data chain, and the audit chain. The operation and maintenance chain is used to record the operation logs and permission changes of the operation and maintenance layer, the data chain is used to store the update records and encryption policies of the central layer, and the audit chain is used to record the full behavior of cross-layer transmission.
[0072] Specifically, the three-dimensional link framework realizes detailed functional partitioning of the blockchain layer and forms a chain-like framework, which can solve the problems of poor collaborative verification mechanism and dynamic response capability of multi-layer data framework. The constructed three-dimensional link framework breaks down the complex blockchain functions into three chains according to business logic. Each chain focuses on data recording and verification in a specific field, avoiding performance limitations and security vulnerabilities caused by the overload of a single chain. A cross-verification mechanism is established between the three-dimensional chains. The operation of any chain requires the collaborative verification of other chains, forming a closed-loop verification security model, thereby improving the system's resistance to attacks.
[0073] Furthermore, key data from each chain has a copy stored in other chains, creating data redundancy and mutual verification. This ensures that even if one chain is attacked, the system can still restore data integrity through other chains, thereby achieving functional coupling and verification mechanisms between the three-dimensional links to further enhance data recovery capabilities.
[0074] As a further extension of this embodiment, the blockchain path in the three-dimensional link is specifically responsible for recording the operation and maintenance layer's operational behavior, which is achieved by recording all operational behaviors and permission change information of the operation and maintenance layer in detail.
[0075] Furthermore, the operational behaviors of the operations and maintenance layer include: e. Equipment configuration changes (timestamp, operator, change content, status before / after change); f. Security policy adjustments (such as modifying firewall rules or updating access control lists); g. System status monitoring data (CPU utilization, memory usage, network traffic, etc.); h. User login and operation behavior (identity identifier after privacy protection processing).
[0076] In addition, permission change information includes: i. Role creation and deletion; j. Permission allocation and revocation; k. Granting and revoking temporary permissions; l. Approval process records for permission changes.
[0077] Furthermore, by optimizing the blockchain layer based on operational data, including using headers with special fields, dynamically adjusting transaction data formats, and adjusting block sizes.
[0078] By adopting an improved PBFT consensus algorithm, the verification nodes are limited to authorized nodes of the operation and maintenance management. The verification results of the data chain and audit chain are introduced into the formula process as a reference. The consensus mechanism is verified by setting a formula timeout trigger mechanism. For example, when the consensus completion time is less than 10 seconds, it is a normal trigger. When it exceeds 10 seconds, it is determined to be an abnormal trigger.
[0079] In addition, operator identity information is verified using zero-knowledge proof technology, and plaintext is not recorded directly. Sensitive configuration data is recorded only by hash value, and raw data is stored in an encrypted storage area. Access logs are recorded according to the principle of minimization, retaining only necessary audit information, thereby enabling the processing of sensitive operation and maintenance data.
[0080] The operations chain and operations layer receive operations operation logs through a dedicated API and provide real-time feedback on the operation record status (success / failure). It also provides a historical operation query interface, supporting multi-dimensional retrieval by time, operation type, operator, and other dimensions.
[0081] The data chain is a blockchain in the three-dimensional chain that is responsible for managing data updates and encryption strategies. It can realize data storage and encryption, receive updates pushed by the data center layer, verify the integrity and reliability of the updated content, and feed back the update status and verification results to the data center layer.
[0082] Furthermore, the data chain provides an encryption policy query interface to the operations and maintenance chain, receives policy application requests from the operations and maintenance chain, and collaborates with the operations and maintenance chain to verify the legality of policy changes. It also synchronizes key policy change records with the audit chain, receives risk assessment results from the audit chain, dynamically adjusts encryption policies, and provides policy execution effect data to the audit chain for risk model optimization.
[0083] The audit chain is the blockchain responsible for full-link security auditing in the three-dimensional chain. It realizes the transmission of full behavior records and security event records across layers. Through interaction with the operation and maintenance chain, it realizes real-time monitoring of the operation and maintenance chain's operation logs, risk assessment of abnormal operation and maintenance behaviors, and sending security instructions to the operation and maintenance chain (such as freezing high-risk accounts).
[0084] Furthermore, the audit chain monitors the data chain's policy changes and update records, assesses the security impact of policy changes, and sends encryption policy adjustment recommendations to the data chain.
[0085] Finally, by receiving independent data interface call data in real time, the legitimacy of the interface call is verified, and abnormal interface calls are subject to flow control or direct blocking.
[0086] Based on the above, the operation and maintenance chain is bound to the data chain, so that the header of each block of the operation and maintenance chain contains the hash value of the latest block of the data chain. When the data chain verifies the operation and maintenance operation, it will check the validity of the hash value.
[0087] Furthermore, the data chain is bound to the audit chain, so that each block header of the data chain contains the latest block height of the audit chain. When verifying data operations, the audit chain will refer to the data status corresponding to that block height.
[0088] Furthermore, the feedback loop between the audit chain and the operations and maintenance chain enables the audit chain to periodically generate security assessment reports, which are then written into special transactions on the operations and maintenance chain. The operations and maintenance chain then automatically adjusts its operations and maintenance strategies based on the security assessment results.
[0089] In the above combination, when any chain detects abnormal behavior, it immediately marks the abnormality in this chain. The abnormality includes risk level, scope of impact, timestamp, and type of abnormality.
[0090] Based on the above, the working principle of the three-dimensional link collaboration is as follows: The three-dimensional link achieves collaborative work through data consistency verification, dynamic risk response, and system self-healing mechanisms: For data consistency verification, the system first locates the corresponding records of cross-layer interactions in the operations chain, data chain, and audit chain. The three chains respectively verify the integrity of operation logs, the correctness of data content, and the compliance of the interaction process. Then, cross-validation is performed to check the matching of operations and data, the consistency between risk assessment and actual operations, and the rationality of the timestamp sequence. Only when the verification results of the three chains are consistent is the data interaction considered complete and trustworthy. For dynamic risk response, the audit chain monitors cross-layer interactions in real time and calculates risk scores. When a threshold is exceeded, a risk event is generated and sent to the operations chain and data chain for cross-chain confirmation. After the three chains collaboratively analyze the root cause of the risk, the operations chain dynamically adjusts its operations strategy, the data chain switches its encryption strategy, and the audit chain optimizes its monitoring parameters. Simultaneously, it monitors the response effect and continuously optimizes the strategy, forming a closed-loop risk management system. For system self-healing, when any chain detects its own anomaly, it sends a self-healing request to the other two chains. By receiving verification proof of missing data and performing cross-validation, the correct state of the abnormal chain is reconstructed. After repair, the cause of the anomaly is analyzed, and protection strategies are strengthened.
[0091] The three mechanisms mentioned above work together to form a secure closed loop from verification and response to recovery, enabling the three-dimensional link to achieve unified verification and risk management of multi-layer data frameworks. By analyzing the correlation data of the three links, the system can predict potential security threats in advance. The division of labor in the three-dimensional link allows each link to optimize resource allocation for specific tasks, thereby improving the overall system resource utilization and processing capacity.
[0092] It should be noted that the above modules can be implemented by software or hardware. For the latter, they can be implemented in the following ways, but are not limited to: all the above modules are located in the same processor; or, the above modules are located in different processors in any combination.
[0093] See attached document Figure 5 A secure communication method for operation and maintenance service management based on blockchain technology includes the following steps: S1. In a three-tier data framework, cross-tier data transmission requests are received through independent data interfaces. S2. The blockchain layer verifies the validity of the requester's identity signature, verifies the matching of the permission level through the operation and maintenance chain, and verifies whether the target address is in the trusted communication whitelist stored in the blockchain through the data chain. S3. After verification, the blockchain layer dynamically matches encryption algorithm combinations based on the data sensitivity level information stored in the operation and maintenance chain, performs fragmented encryption processing on the transmitted data, and generates encrypted transmission channel parameters in the data chain. S4. Transmit the encrypted data fragments to the target data layer through an independent data interface. The operation and maintenance layer collects at least k key fragments to reassemble the data. The data center layer only provides the amount of data authorized by the audit chain. S5. The three-layer data framework collaboratively records the complete cross-layer transmission behavior, the operation and maintenance chain records operation logs, the data chain stores encrypted parameters, and the audit chain stores the full-link transmission information, realizing data consistency verification through the three-dimensional link.
[0094] According to the appendix Figure 6 In step S5, the data consistency verification method includes the following steps: S501. Verify data consistency by checking the latest block hash value of the data chain contained in the operation and maintenance chain block header; S502. Verify whether the latest block height of the audit chain contained in the data chain block header matches; S503 employs lightweight client technology to achieve cross-chain verification, ensuring that the verification process is efficient and reliable.
[0095] As an optional embodiment, a secure communication method for operation and maintenance service management based on blockchain technology further includes the following steps for risk response effectiveness assessment: S6. Monitor the effectiveness of risk response measures; S7. Dynamically adjust subsequent security strategies based on the response results; S8. Record effective risk response strategies in a knowledge base for use in optimizing future risk responses.
[0096] Based on the above steps, when data is transmitted between the three-layer data framework, the system will automatically perform security checks: verifying identity, matching permissions, and verifying the whitelist in sequence. After verification, an encryption scheme is customized according to the sensitivity of the data, and the data is split into multiple fragments and encrypted and transmitted separately. Even if an attacker obtains some fragments, they will not be able to piece together the complete information, thus ensuring the security of the data.
[0097] The mutual verification between the three-dimensional links enables other links to immediately detect and assist in repairing an anomaly when one link malfunctions. This achieves supervision and correction between the three-dimensional links, upgrading security protection from passive defense to active immunity and improving risk response speed.
[0098] Furthermore, it can enhance the system's self-learning ability, thereby continuously improving the system's security capabilities.
[0099] As an optional embodiment, refer to the appendix Figure 7 The three-tier data framework collaboration method includes the following steps: S101, the operation and maintenance layer is deployed on the intranet and interacts with the blockchain layer only through an independent data interface. The stored operation and maintenance data is saved in a full-scale sharded encryption method. When data needs to be updated, an update request is sent to the blockchain layer through the independent data interface. S102. After receiving the update request from the operation and maintenance layer, the blockchain layer verifies the requester's permissions through the operation and maintenance chain and queries the trusted communication whitelist through the data chain to confirm the push permissions of the data center layer. The permission verification result is recorded to the audit chain in real time. S103. Based on the permission verification results of the blockchain layer, the data center layer pushes updated data to the operation and maintenance layer through an independent data interface. The push process is monitored by the blockchain layer, and the amount of operation and maintenance data transmitted is limited by the authorization of the audit chain. S104. During data transmission, the three-dimensional link forms a collaborative verification mechanism through cross-hash binding. The operation and maintenance chain block header contains the latest block hash value of the data chain, and the data chain block header contains the latest block height of the audit chain. Any abnormal data in any link of the three-dimensional link will trigger the three-dimensional link collaborative blocking mechanism.
[0100] As an optional embodiment, refer to the appendix Figure 8 The dynamic encryption and risk management method of the three-layer data framework includes the following steps: S201. When the blockchain layer detects that the cross-layer transmission risk score exceeds the threshold, it notifies the operation and maintenance layer through the operation and maintenance chain to reduce the data transmission volume or stop the data transmission. At the same time, it instructs the data center layer to switch to the quantum-resistant encryption algorithm through the data chain. S202. The operation and maintenance layer adjusts the data receiving strategy according to the instructions of the operation and maintenance chain, only receiving key data authorized by the audit chain, and at the same time feeding back the system status to the blockchain layer. S203. The data center layer dynamically adjusts the push strategy according to the instructions of the data link, and adopts fragmented encrypted transmission for high-risk transmission, with each fragment of data processed using a different encryption algorithm. S204. The audit chain monitors the three-dimensional link collaboration status in real time. When an abnormality in data consistency is detected, it automatically generates a full-link traceability report and triggers the smart contract to freeze the relevant data interfaces.
[0101] As an optional implementation, the key management mechanism of the three-tier data architecture includes: S301. The updated data pushed by the data center layer is split into n shards, and the encryption key of each shard is divided into k shards, which are stored in different nodes of the blockchain layer respectively. S302. When the operation and maintenance layer reorganizes data, it needs to initiate a key fragmentation request to the blockchain layer through the operation and maintenance chain, collect at least k key fragments, and then decrypt them through threshold signature technology. S303. The complete record of the key fragmentation request and reassembly process is stored in the audit chain, forming an immutable key usage audit trail; S304. When an abnormal key usage pattern is detected, the audit chain triggers a smart contract to update the key sharding strategy and notifies the operations layer to suspend data reassembly through the operations chain.
[0102] According to another aspect of the present invention, an electronic device is also provided, the electronic device including a memory and a processor; the memory is used to store a program; the processor executes the program to implement the method of any of the foregoing.
[0103] According to another aspect of the present invention, a computer-readable storage medium is also provided, the storage medium storing a computer program that, when executed by a processor, implements the method of any of the foregoing.
[0104] According to another aspect of the present invention, a computer program product is also provided, including a computer program that, when executed by a processor, implements the method described in any of the foregoing.
[0105] The above description is merely a preferred embodiment of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention. Structures, devices, and operating methods not specifically described or explained in this invention are implemented according to conventional methods in the art unless otherwise specified or limited.
Claims
1. A secure communication system for operation and maintenance service management based on blockchain technology, characterized in that, include: A three-tier data framework, comprising: The operation and maintenance layer is deployed on the intranet. The operation and maintenance layer is used to store operation and maintenance service data, run operation and maintenance systems and communication systems, and output full data fragments and encrypted storage to the operation and maintenance layer. The data center layer is used to store real-time updated secure communication protocols, defense system patches, and encryption policy libraries. It interacts with the operation and maintenance layer and the blockchain layer through an independent data interface, and only allows authorized cross-layer data requests. The blockchain layer is used to record all data interaction behaviors between the three-layer data framework, verify the legality of cross-layer transmission requests through smart contracts, and generate encrypted transmission channels. as well as A cross-layer transmission control module is used to implement data transmission, data encryption, and data transmission monitoring in a three-layer data framework. A blockchain encryption recording module is used to realize cross-layer data interaction encryption, recording, and monitoring within a three-layer data framework.
2. The secure communication system for operation and maintenance service management based on blockchain technology according to claim 1, characterized in that, The cross-layer transmission control module includes: Dynamic encryption strategy engine: Matches encryption algorithms based on data sensitivity levels; Transmission direction control unit: Based on a blockchain-stored trusted communication whitelist, it restricts the transmission of data from the data center layer to the operation and maintenance layer, including the authorized data size, data type, data source and communication protocol; Hierarchical permission response mechanism: When the operations and maintenance layer requests data, it must submit identity credentials and verify them through zero-knowledge proof. Permission changes are synchronized on the blockchain in real time.
3. The secure communication system for operation and maintenance service management based on blockchain technology according to claim 1, characterized in that: The blockchain encryption recording module generates a unique hash value for all cross-layer data interactions and writes it into the blockchain layer, and records it in the blockchain layer's log to achieve full-link traceability of cross-layer data interactions, as well as trigger smart contract alarms and freeze the corresponding interfaces for abnormal transmission behavior.
4. The secure communication system for operation and maintenance service management based on blockchain technology according to claim 1, characterized in that, The independent data interface includes: Interface identity binding unit: Each interface is uniquely associated with a blockchain layer address to prevent illegal interface requests; Traffic rate limiting controller: Limits the rate of cross-layer data transmission to prevent data leakage or DDoS attacks; Protocol Adaptive Converter: Automatically adapts to the communication protocols between the three-layer data framework, achieving compatibility for cross-layer data interaction.
5. A secure communication system for operation and maintenance service management based on blockchain technology as described in claim 1, characterized in that: The blockchain layer includes three-dimensional links, which are set up independently and interact with each other through a set cross-chain protocol. The three-dimensional link includes an operation and maintenance chain, a data chain, and an audit chain. The operation and maintenance chain is used to record the operation logs and permission changes of the operation and maintenance layer. The data chain is used to store the update records and encryption policies of the central layer. The audit chain is used to record the full behavior of cross-layer transmission.
6. A secure communication method for operation and maintenance service management based on blockchain technology, applied to the system described in any one of claims 1-5, characterized in that, Includes the following steps: In a three-tier data framework, cross-tier data transmission requests are received through independent data interfaces; The blockchain layer verifies the validity of the requester's identity signature, while the operation and maintenance chain verifies the matching of the permission level, and the data chain verifies whether the target address is in the trusted communication whitelist stored in the blockchain. After verification, the blockchain layer dynamically matches encryption algorithm combinations based on the data sensitivity level information stored in the operation and maintenance chain, performs fragmented encryption processing on the transmitted data, and generates encrypted transmission channel parameters in the data chain; The encrypted data fragments are transmitted to the target data layer through independent data interfaces. The operation and maintenance layer collects at least k key fragments to reassemble the data, and the data center layer only provides the amount of data authorized by the audit chain. The three-layer data framework collaboratively records the complete cross-layer transmission behavior, the operation and maintenance chain records operation logs, the data chain stores encrypted parameters, and the audit chain stores the full-link transmission information, realizing data consistency verification through the three-dimensional link.
7. A secure communication method for operation and maintenance service management based on blockchain technology according to claim 6, characterized in that, The three-layer data framework collaboration method includes the following steps: The operations and maintenance layer is deployed on the intranet and interacts with the blockchain layer only through an independent data interface. The stored operations and maintenance data is saved in a fully sharded and encrypted manner. When data needs to be updated, an update request is sent to the blockchain layer through the independent data interface. After receiving an update request from the operations and maintenance layer, the blockchain layer verifies the requester's permissions through the operations and maintenance chain and queries the trusted communication whitelist through the data chain to confirm the data center layer's push permissions. The permission verification result is recorded to the audit chain in real time. Based on the permission verification results of the blockchain layer, the data center layer pushes updated data to the operations and maintenance layer through an independent data interface. The push process is monitored by the blockchain layer, and the amount of data transmitted by the operations and maintenance layer is limited by the authorization of the audit chain. During data transmission, the three-dimensional link forms a collaborative verification mechanism through cross-hash binding. The operation and maintenance chain block header contains the latest block hash value of the data chain, and the data chain block header contains the latest block height of the audit chain. Any abnormal data in any link of the three-dimensional link will trigger the three-dimensional link collaborative blocking mechanism.
8. A secure communication method for operation and maintenance service management based on blockchain technology according to claim 6, characterized in that, The dynamic encryption and risk management method of the three-layer data framework includes the following steps: When the blockchain layer detects that the risk score of cross-layer transmission exceeds the threshold, it notifies the operation and maintenance layer through the operation and maintenance chain to reduce the amount of data transmission or stop data transmission. At the same time, it instructs the data center layer to switch to a quantum-resistant encryption algorithm through the data chain. The operations and maintenance layer adjusts its data receiving strategy according to the instructions of the operations and maintenance chain, only receiving key data authorized by the audit chain, and at the same time feeding back the system status to the blockchain layer; The data center layer dynamically adjusts the push strategy according to the instructions of the data chain, and adopts fragmented encrypted transmission for high-risk transmissions, with each fragment of data processed using a different encryption algorithm; The audit chain monitors the three-dimensional link collaboration status in real time. When an anomaly in data consistency is detected, it automatically generates a full-link traceability report and triggers a smart contract to freeze the relevant data interfaces.
9. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 6 to 8.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 6 to 8.
Citation Information
Cited By
Transformer area edge safety linkage method based on electricity utilization information acquisition terminal
CN121309212A